CVE-2007-5936

dvips in teTeX and TeXlive 2007 and earlier allows local users to obtain sensitive information and modify certain data by creating certain temporary files before they are processed by dviljk, which can then be read or modified in place.
References
Link Resource
http://bugs.gentoo.org/attachment.cgi?id=135423
http://bugs.gentoo.org/show_bug.cgi?id=198238
http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html
http://osvdb.org/42238
http://secunia.com/advisories/27672 Vendor Advisory
http://secunia.com/advisories/27686 Vendor Advisory
http://secunia.com/advisories/27718 Vendor Advisory
http://secunia.com/advisories/27743 Vendor Advisory
http://secunia.com/advisories/27967 Vendor Advisory
http://secunia.com/advisories/28107 Vendor Advisory
http://secunia.com/advisories/28412 Vendor Advisory
http://secunia.com/advisories/30168 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200711-26.xml
http://security.gentoo.org/glsa/glsa-200711-34.xml
http://security.gentoo.org/glsa/glsa-200805-13.xml
http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0266
http://www.mandriva.com/security/advisories?name=MDKSA-2007:230
http://www.securityfocus.com/archive/1/487984/100/0/threaded
http://www.securityfocus.com/bid/26469
http://www.securitytracker.com/id?1019058
http://www.vupen.com/english/advisories/2007/3896
https://bugzilla.redhat.com/show_bug.cgi?id=368611
https://issues.rpath.com/browse/RPL-1928
https://usn.ubuntu.com/554-1/
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00663.html
http://bugs.gentoo.org/attachment.cgi?id=135423
http://bugs.gentoo.org/show_bug.cgi?id=198238
http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html
http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html
http://osvdb.org/42238
http://secunia.com/advisories/27672 Vendor Advisory
http://secunia.com/advisories/27686 Vendor Advisory
http://secunia.com/advisories/27718 Vendor Advisory
http://secunia.com/advisories/27743 Vendor Advisory
http://secunia.com/advisories/27967 Vendor Advisory
http://secunia.com/advisories/28107 Vendor Advisory
http://secunia.com/advisories/28412 Vendor Advisory
http://secunia.com/advisories/30168 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200711-26.xml
http://security.gentoo.org/glsa/glsa-200711-34.xml
http://security.gentoo.org/glsa/glsa-200805-13.xml
http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0266
http://www.mandriva.com/security/advisories?name=MDKSA-2007:230
http://www.securityfocus.com/archive/1/487984/100/0/threaded
http://www.securityfocus.com/bid/26469
http://www.securitytracker.com/id?1019058
http://www.vupen.com/english/advisories/2007/3896
https://bugzilla.redhat.com/show_bug.cgi?id=368611
https://issues.rpath.com/browse/RPL-1928
https://usn.ubuntu.com/554-1/
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00663.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tetex:tetex:*:*:*:*:*:*:*:*
cpe:2.3:a:tug:texlive_2007:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:38

Type Values Removed Values Added
References () http://bugs.gentoo.org/attachment.cgi?id=135423 - () http://bugs.gentoo.org/attachment.cgi?id=135423 -
References () http://bugs.gentoo.org/show_bug.cgi?id=198238 - () http://bugs.gentoo.org/show_bug.cgi?id=198238 -
References () http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html - () http://lists.opensuse.org/opensuse-security-announce/2008-01/msg00002.html -
References () http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html - () http://lists.opensuse.org/opensuse-security-announce/2008-05/msg00000.html -
References () http://osvdb.org/42238 - () http://osvdb.org/42238 -
References () http://secunia.com/advisories/27672 - Vendor Advisory () http://secunia.com/advisories/27672 - Vendor Advisory
References () http://secunia.com/advisories/27686 - Vendor Advisory () http://secunia.com/advisories/27686 - Vendor Advisory
References () http://secunia.com/advisories/27718 - Vendor Advisory () http://secunia.com/advisories/27718 - Vendor Advisory
References () http://secunia.com/advisories/27743 - Vendor Advisory () http://secunia.com/advisories/27743 - Vendor Advisory
References () http://secunia.com/advisories/27967 - Vendor Advisory () http://secunia.com/advisories/27967 - Vendor Advisory
References () http://secunia.com/advisories/28107 - Vendor Advisory () http://secunia.com/advisories/28107 - Vendor Advisory
References () http://secunia.com/advisories/28412 - Vendor Advisory () http://secunia.com/advisories/28412 - Vendor Advisory
References () http://secunia.com/advisories/30168 - Vendor Advisory () http://secunia.com/advisories/30168 - Vendor Advisory
References () http://security.gentoo.org/glsa/glsa-200711-26.xml - () http://security.gentoo.org/glsa/glsa-200711-26.xml -
References () http://security.gentoo.org/glsa/glsa-200711-34.xml - () http://security.gentoo.org/glsa/glsa-200711-34.xml -
References () http://security.gentoo.org/glsa/glsa-200805-13.xml - () http://security.gentoo.org/glsa/glsa-200805-13.xml -
References () http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0266 - () http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0266 -
References () http://www.mandriva.com/security/advisories?name=MDKSA-2007:230 - () http://www.mandriva.com/security/advisories?name=MDKSA-2007:230 -
References () http://www.securityfocus.com/archive/1/487984/100/0/threaded - () http://www.securityfocus.com/archive/1/487984/100/0/threaded -
References () http://www.securityfocus.com/bid/26469 - () http://www.securityfocus.com/bid/26469 -
References () http://www.securitytracker.com/id?1019058 - () http://www.securitytracker.com/id?1019058 -
References () http://www.vupen.com/english/advisories/2007/3896 - () http://www.vupen.com/english/advisories/2007/3896 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=368611 - () https://bugzilla.redhat.com/show_bug.cgi?id=368611 -
References () https://issues.rpath.com/browse/RPL-1928 - () https://issues.rpath.com/browse/RPL-1928 -
References () https://usn.ubuntu.com/554-1/ - () https://usn.ubuntu.com/554-1/ -
References () https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00663.html - () https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00663.html -

Information

Published : 2007-11-13 22:46

Updated : 2024-11-21 00:38


NVD link : CVE-2007-5936

Mitre link : CVE-2007-5936

CVE.ORG link : CVE-2007-5936


JSON object : View

Products Affected

tetex

  • tetex

tug

  • texlive_2007
CWE
CWE-264

Permissions, Privileges, and Access Controls